Privacy policy · Updated October 3, 2026
Your documents stay on your Mac.
Blank fills, signs, and exports PDFs locally. This policy explains the information used to deliver the website, optional analytics, purchases, and support.
Who we are
Joshua Tonga, the maker of Blank at TinyInternet, is responsible for the information described here. For privacy questions or requests, email hello@tinyinternet.dev.
Documents and signatures stay local
Your imported PDFs, drafts, saved profile details, and reusable signatures are stored on your Mac. Filling, field detection, signing, and exporting happen on the device. Blank does not upload this content to a document server or AI service, and does not require a Blank account.
Removing a document from Blank moves its workspace files to Blank’s local Trash directory; it does not securely erase them or delete the original file. Exports, device backups, and copies you share or store with other services remain separate. See Support for help managing local documents.
Optional usage analytics
Website and Mac app analytics are off until you allow them. These are separate choices. We use consented activity to understand activation, repeat use, feature adoption, and purchase interest.
Website events describe visits to our published pages, page departures, download clicks, and successful checkout starts. They include the public page address without queries or fragments, time between page arrival and departure, how far down the page you scroll (distances and percentages), browser and operating-system names, and device category (desktop, mobile, or tablet). We do not send the raw browser user-agent string, browser or operating-system versions, or hardware model. App events describe launches, imports, exports, feature use, trial limits, purchase clicks, and submitted license-activation outcomes. App metadata can include app version, export format, sample-document status, free or paid access, and general failure categories.
Consented website events can also include campaign labels from allowlisted UTM parameters and the referring website’s domain, without its full address. We remember first and most recent attribution for up to 30 days. Google advertising click identifiers are kept separate and are not sent to PostHog.
If you allow usage analytics when starting checkout, a confirmed purchase or refund can be associated with the same anonymous website identifier. These events contain an order reference, product, currency, and amounts, but not your name, email, license key, or payment-card information.
This is pseudonymous usage data. A random identifier is created only after consent, stored in your browser’s local storage or the app’s local preferences, and kept separate between website and app. It is not derived from hardware, email, licenses, or documents.
The website also stores a random session identifier to group visits in the same browser. A new session starts after 30 minutes without tracked activity or after 24 hours. Turning analytics off removes both website identifiers.
Usage events exclude document contents, filenames, document paths, form answers, signatures, saved profile details, emails, license keys, payment-card details, raw error messages, raw URL queries and fragments, and full referrer URLs. We do not use session replay, autocapture, surveys, automatic error capture, or person profiles.
PostHog processes analytics in its US cloud. Browser analytics requests pass through our domain and hosting provider, Vercel, before reaching PostHog. Confirmed purchase and refund events are sent by our server. Both require the same optional analytics consent. Location enrichment is disabled and client IP addresses are discarded from stored events. The infrastructure handling browser requests still receives connection information, including your IP address. Our current plan retains usage events for one year.
Optional ad measurement
Google Ads measurement is a separate website choice from PostHog usage analytics. It stays off until you allow it in Privacy settings. Accepting usage analytics in the past does not enable ad measurement.
When you allow ad measurement, Google’s tag can use advertising cookies and browser and connection information to measure our ads. We can store Google click identifiers and campaign labels in your browser for up to 30 days. If you start checkout while ad measurement is enabled, that permitted attribution can be included in a server consent context for up to 90 days. Confirmed-purchase measurement uses an order reference, purchase amount, and currency to count an order once; refunds can adjust that measurement. Google receives the public page address without private queries or fragments. We do not send PDF contents, form answers, saved signatures, email addresses, license keys, or payment-card information to Google Ads.
We do not enable personalized advertising, remarketing, or Google Analytics. Google’s advertising tags are blocked before permission; we do not use cookieless Google measurement when you decline. See how Google uses information from sites that use its services.
Change your choice at any time
Use Privacy settings in the website footer to manage usage analytics and ad measurement independently, or Settings → Privacy in Blank for app analytics. Declining does not limit features or checkout. Your preferences are remembered locally.
Turning analytics off stops new collection, cancels pending requests where possible, and clears the local identifier and pending app events. Already transmitted events cannot be recalled; opting out does not delete them from PostHog. Allowing analytics again creates a new identifier.
Turning ad measurement off clears advertising cookies set on our domain and stored ad attribution. If Google’s tag has already loaded, the page reloads to stop it running. This does not delete information already sent to Google or cookies on Google’s own domains.
To apply a later withdrawal to a checkout already started in this browser, we store a withdrawal receipt for up to 90 days, matching the server’s checkout consent context. Withdrawal requests that cannot reach the server can be retried when you revisit the site or reconnect. Clearing browser storage removes those receipts, so we may no longer be able to connect a later choice to an earlier checkout. Already delivered measurement cannot be recalled.
Website visits, downloads, and checkout-start events have no event queue or retries. Confirmed purchase and refund measurement can retry from our server. The Mac app may retain up to 500 consented events locally for up to seven days while attempting delivery.
Purchases, licensing, and delivery
Dodo Payments handles checkout, payment information, receipts, and license delivery. We can access purchase records needed for billing and support, but not your full payment-card details. The app sends a license key and activation information to Dodo for activation, validation, and deactivation. It does not send documents, a hardware identifier, or your Mac’s hostname. License and trial records are stored locally in macOS Keychain.
Our server uses Supabase to store checkout consent contexts for up to 90 days and process confirmed payment measurement reliably. These contexts contain the permitted anonymous analytics or ad identifiers and campaign labels. Separate records retain order and refund references, amounts, webhook identifiers, and delivery status for reconciliation and to prevent duplicate events. They exclude names, email addresses, license keys, payment-card details, and document content. Clearing a consent context does not automatically delete these separate records.
Vercel hosts this website. Cloudflare delivers app downloads and updates. These services process request and connection information to deliver and protect their services. App update checks are separate from optional analytics; Sparkle system profiling is disabled. We do not use Vercel Web Analytics or Speed Insights.
Support and other records
If you email us, we and our email provider receive your address, message, and any attachments you choose to send. We use them to respond and troubleshoot. Please remove private document contents and never send full license keys or payment-card details.
Support correspondence is retained as needed for the request, follow-up, disputes, and legal requirements. Payment and hosting providers retain operational records under their policies and applicable obligations. We do not promise that opting out of analytics erases those separate records. We do not sell personal information.
Your rights and contact
Where applicable, processing relies on consent for optional analytics, providing requested services, legitimate interests in support and security, and legal obligations. Providers may process information outside your country; their policies explain applicable processing and safeguards. No storage or transmission method guarantees complete security.
Depending on your location, you may request access, correction, deletion, or a copy of your information, object to or restrict processing, withdraw consent, or complain to your privacy regulator. Email hello@tinyinternet.dev. We may need to verify a request; because analytics identifiers are separate from your email, we may be unable to associate past events with you.
We will update the date above when this policy changes and provide additional notice where required. Visit Support for product help or read the Terms of use.